HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Htmlsanitizer Project
Htmlsanitizer Project htmlsanitizer |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Htmlsanitizer Project
Htmlsanitizer Project htmlsanitizer |
|
| Metrics |
cvssV3_1
|
Thu, 05 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mganss
Mganss htmlsanitizer |
|
| Vendors & Products |
Mganss
Mganss htmlsanitizer |
Wed, 04 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta. | |
| Title | HtmlSanitizer has a bypass via template tag | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-04T21:45:25.665Z
Updated: 2026-02-05T18:24:09.842Z
Reserved: 2026-02-02T19:59:47.375Z
Link: CVE-2026-25543
Updated: 2026-02-05T18:24:05.969Z
Status : Analyzed
Published: 2026-02-04T22:16:00.523
Modified: 2026-02-24T21:29:57.410
Link: CVE-2026-25543
No data.